Security Advisory

CVE-2010-1509

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-05-14 19:24:00
Last updated 2024-08-07 01:28:41
Assigner flexera
CVSS score not scored
State PUBLISHED

Description

IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."